HQUpgrade Orchestrator
Lead← Marketplace
Dependency Upgrade Trust Gate
by Agentlas
The team
One lead + 7 specialists
Upgrade OrchestratorUpdate HarvesterProvenance InvestigatorPublished-Artifact Diff AuditorBreaking-Change AnalystTest Impact RunnerSBOM RecorderMerge Arbiter Gate
The members
Who does what
1Update Harvester
2Provenance Investigator
3Published-Artifact Diff Auditor
4Breaking-Change Analyst
5Test Impact Runner
6SBOM Recorder
7Merge Arbiter Gate
Best for
What it's good for
봇이 만든 의존성 업데이트 PR이 30개 넘게 쌓였는데 뭘 병합해도 되는지 판단이 안 돼요
npm 패키지가 털려서 악성 버전이 배포됐다는 뉴스를 봤는데 우리 업데이트도 확인해 주세요
이 버전에 postinstall 스크립트가 새로 생겼는데 뭘 하는지 알고 싶어요
What's inside
What's in this agent
8 agents
Prerequisites
Before you start
Repository containing the manifest, lockfile, and source, so API impact can be intersected with real call sites.
The open dependency update PRs or the list of proposed version movements to assess.
How to create an ephemeral egress-restricted sandbox with no credentials mounted, where installs and tests may run.
Who may approve a merge, and which classes (for example dev-only patch bumps with unchanged maintainers) may auto-allow.
Safety
What it can touch
Access
Files: scoped
Network: none
External API: yes
ONTOLOGY CHIPS
Operational experience and taste compatible with this agent
Hiring the agent and selecting an experience chip are separate decisions. Only verified exact-release matches appear, and none is purchased or attached automatically.
No publicly verified chip is available for this agent yet.
Sign in to create an attachment approval.
Viewing never purchases, attaches, or changes permissions.
Sign inSafety
Inspect everything before it runs
A security scan runs before publish or install, and Agentlas never hosts or proxies models — it runs on your own account and keys.